CVE-2026-83138
moderatePrivileged Takeover Flaw in Oracle Spares Management for E-Business Suite
A difficult-to-exploit vulnerability in the Internal Operations component of Oracle Spares Management allows an attacker who already holds high privileges and has network access via HTTP to fully compromise the product. Successful attacks result in a complete takeover of Oracle Spares Management with high confidentiality, integrity, and availability impact, and because of a scope change the blast radius can extend to additional products in the E-Business Suite environment. The affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running the Spares Management product. The high privilege requirement and high attack complexity make opportunistic exploitation unlikely, but a compromised privileged account or malicious insider could abuse the flaw for lateral impact. No public proof of concept is known and no in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83138 to all E-Business Suite 12.2.3-12.2.15 environments running Spares Management. Restrict HTTP access to EBS internal operations endpoints to trusted networks and VPNs, and audit high-privileged account activity for misuse. Confirm whether Spares Management is deployed and enabled, since environments without the module are not directly exposed to this flaw.
| Oracle Spares Management (Oracle E-Business Suite), Internal Operations component | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Spares Management. While the vulnerability is in Oracle Spares Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.